PT-2026-26878 · WordPress · Neos Connector For Fakturama

Muhammad Afnaan

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-4143

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Neos Connector for Fakturama plugin for WordPress versions up to and including 0.0.14
Description The Neos Connector for Fakturama plugin for WordPress is susceptible to Cross-Site Request Forgery. This is a result of a lack of nonce validation in the ncff add plugin page() function, which manages settings updates. An unauthenticated attacker could potentially modify plugin settings by tricking a site administrator into performing an action, such as clicking a malicious link.
Recommendations Update the Neos Connector for Fakturama plugin to a version later than 0.0.14.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-4143

Affected Products

Neos Connector For Fakturama